VDB

CVE-2019-1201

CVE-2019-1201 PUBLISHED CVSS 7.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1205.

EPSS 11.30% · 93.7th percentile

Risk Scores

CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
11.30%
93.7th percentile

Affected Products

VendorProductVersions
microsoftsharepoint_enterprise_server2013, 2016
MicrosoftOffice 365 ProPlus16.0.0
microsoftsharepoint_server2019, 2010
microsoftoffice_online_server
MicrosoftMicrosoft Word 2010 Service Pack 213.0.0.0
MicrosoftMicrosoft SharePoint Server 201916.0.0
MicrosoftMicrosoft SharePoint Enterprise Server 201616.0.0
MicrosoftMicrosoft Office 2016 for Mac16.0.0
MicrosoftMicrosoft SharePoint Enterprise Server 2013 Service Pack 115.0.0
MicrosoftMicrosoft Office 2019 for Mac16.0.0
MicrosoftMicrosoft Office 2010 Service Pack 213.0.0.0
microsoftoffice_web_apps2010
microsoftoffice_web_apps_server2013
MicrosoftMicrosoft Office Online Server16.0.1
microsoftword2013, 2010, 2013
MicrosoftMicrosoft Word 201616.0.1
MicrosoftMicrosoft Office Web Apps Server 2013 Service Pack 115.0.1
microsoftoffice_365_proplus
microsoftoffice2019, 2019, 2016
MicrosoftMicrosoft Office 201919.0.0

…and 3 more

Timeline

  • Aug 14, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
  • May 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›